vulnerability
MFSA2026-11 Thunderbird: Security Vulnerabilities fixed in Thunderbird 147.0.2 and 140.7.2 (CVE-2026-2447)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:M/Au:N/C:C/I:C/A:C) | Feb 16, 2026 | Feb 17, 2026 | Apr 15, 2026 |
Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Feb 16, 2026
Added
Feb 17, 2026
Modified
Apr 15, 2026
Description
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
Solutions
mozilla-thunderbird-upgrade-140_7_2mozilla-thunderbird-upgrade-147_0_2
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.